
CVE-2026-25724 Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files thro… https://www.cve.org/CVERecord?id=CVE-2026-25724
Post summary
Claude Code before v2.1.7 did not enforce deny rules set in settings.json for file access, indicating a potential vulnerability (CVE‑2026‑25724).


